TFS 2010 Web Deploy Unauthorized Operation During Build

I’ve been working on using web deploy to automate our builds of some particular web sites we have built internally.  I’m using Web Deploy 2.0, IIS 7.5, and TFS 2010.  It’s been working fine until today when we get this message:

C:\Program Files (x86)\MSBuild\Microsoft\VisualStudio\v10.0\Web\Microsoft.Web.Publishing.targets (3847): Web deployment task failed.  An error occurred when the request was processed on the remote computer. Failed to invoke or execute createApp provider on the web server.  The Web Deployment Tool’s createApp provider is either not enabled or failed to executed specific commands on the server.  Please contact your server administrator for assistance. (Web Deploy Provider is "createApp"). Error details: An error occurred when the request was processed on the remote computer. Attempted to perform an unauthorized operation. createApp http://go.microsoft.com/fwlink/?LinkId=178034

I search around and found that “createApp” is one of the Providers in the IIS Manage Service Delegations (see image below).  Initially when I was setting up web deploy I was following someone blog post on this and their recommendation was using “contentPath, iisApp, setAcl” which worked until today.  When I added “createApp” it fixed the issue.  See my blog on setting up web deploy.

image

Report Manager URL Not Using SSL SSRS 2008 R2

If you’re using SQL Server Reporting Services 2008R2 and have configured it to use SSL but are having issues in Report Manager where the context menus and other links are non-SSL, read on.  Apparently when you follow the simple steps to enable SSL with a certificate that you’ve installed on your Report Manager machine, they don’t point out that you need to remove the the port 80 URL otherwise Report Manager links won’t always be https!  Follow the steps below to fix this issue.

1.  Open the Report Service Configuration Manager.

2.  Go to the Web Service URL tab on the left.  Click the Advanced… button.  Remove the HTTP identity of the report server.  Click OK.

image

After it is removed for the Web Server you should see the following.

image

3.  Now navigate to the Report Manager URL.  Click the Advanced… button.  Remove the HTTP identity of the report server.  Click OK.

image

After it is removed for the Web Server you should see the following.

image

Using SSL and TFS 2010 for Reporting Services All-In-One Install

A current deployment I’m working on for TFS requires that everything use SSL, which includes the TFS part and SQL Reporting Services (SSRS) reports (report manager/report web services).  We are diving into customization on some of the reports and someone mentioned that our Reports folder in Visual Studio has a red X on it (see below).

image

Everything else with regard to TFS was working fine over SSL, we could even access the report manager for SSRS, so I knew it had to be some in TFS that drove Visual Studio and the link in the Team Web Access.  Follow the steps below to fix this predicament.

1.  Log on to your TFS server and open the TFS administration console.
2.  Select the Reporting node in the left navigator

image

3.  Click the Edit link on the right side of the screen.  It will ask if you want to stop the schedule jobs, click OK.  A dialog with 3 tabs will come up.  Select the Reports tab.  In this tab, set the Web Service and the Report Manager to the SSL base URLs that represent your SSRS installation, for example https://tfs.mytfsmachine.com.  Note that once you change the Web Service url you will have to re-enter the data source user’s password.  Once you have update the fields, click OK.  See the image below.

image

4.  Start the jobs again by clicking “Start Jobs” on the right.  You are done.

To check that it all works go into Visual Studio and connect to your TFS server.  The red X should be gone from a team project’s Reports folder.  Also check you Team Web Access (https://{your dns name}/tfs/web/) to make sure that the link to the reports from the web page correctly uses the SSL url.

IIS 7 and Later Application Pool Folder Permissions

The other day I was creating a static web site in Windows 2008R2, and after creating the site I kept getting an access denied.  I scratched my head for a bit as in the past with IIS 6 it usually just worked the first time.  In IIS 7+, the new site will default to creating a new application pool.  Also in the past there were issue with application pools being run under Network Service since this was a built in account.  Now these new application pools run under ApplicationPoolIdentity, but the caveat is that you have to apply folder permissions so that the new application pool can read your web content; this wouldn’t apply if you are running the pool under a dedicated local or AD account.  After searching for a while I found that in order to assign folder permission like you would any other user, you have to use this user name convention "IIS APPPOOL\{YourAppPoolName}” where {YourAppPoolName} is the name of your application pool.  With this information you can go to you folder’s properties and set the permissions accordingly.